# Hook0 (slim) > Hook0 is a webhook sending service from FGRibreau SARL in France. An application posts events to a REST API and Hook0 signs, retries and logs deliveries to subscriber endpoints. It runs as an EU-hosted cloud or self-hosted under SSPL-1.0. - Full: https://www.anchorterminal.com/tools/hook0.md (~7,850 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/hook0.json · canonical https://www.anchorterminal.com/tools/hook0 - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **B · 64.6/100 · rank #313 of 842 · #5 in Event delivery & webhooks · not agent-ready · confidence medium** Assessment: Hook0 Cloud sends signed webhooks from one REST call, with a public OpenAPI document, RFC 7807 errors and service tokens that can be narrowed offline to one application, an expiry or read-only actions. Six security advisories were published between August and September 2026, one rated High. Signup needs a browser check, and no uptime commitment exists below Enterprise. ## Facts - Kind: HTTP API · vendor: FGRibreau SARL · category: Event delivery & webhooks · legal entity: FGRibreau SARL · provenance 91/100 - Local only (HTTP, stdio): npm `hook0-client`, pypi `hook0-client`, cargo `hook0-mcp` - Auth: API key · pricing: Freemium · x402: no · licence: SSPL-1.0 for the server (source available, not an OSI licence). The SDKs and the `hook0-mcp` server are MIT per crates.io and npm. Hook0 Cloud is a hosted service under Hook0's terms of service - Probe metrics: not measured yet (probes haven't run) - API: REST at https://app.hook0.com/api/v1, version 1.0.2, OpenAPI 3.0 with 56 operations on 38 paths. 36 are tagged for the SDKs and 23 for the MCP server - MCP server: `hook0-mcp` 3.0.0 on crates.io, stdio only, 23 tools named `.`, eight `hook0://` resources and three prompts. It makes one attempt per call and no retries - Credentials: Biscuit service tokens per organisation, narrowed offline by application, expiry or action list. Application secrets with full control of one application. Bearer header only - Rate limits: 10 requests a second per token, 100 per IP and 1,000 overall, per the API introduction. Daily event quotas of 100, 30,000 and 100,000 by plan - Errors: RFC 7807 problems with `type`, `id`, `title`, `detail` and `status`. 46 codes in the reference. 429 carries `Retry-After` - Idempotency: Optional client `event_id` (UUID). A repeat is rejected with `EventAlreadyIngested` (409). `POST /api/v1/events/{event_id}/replay` resends an event to matching subscriptions - Retries: From 3 seconds to 10 hours between attempts, 24 retries by default, with slower delivery to subscriptions whose endpoints are failing - Signatures: HMAC-SHA256 in `X-Hook0-Signature` with a timestamp, the signed header names and a `v1` signature, keyed by the subscription's secret - SDKs: JavaScript and TypeScript, Rust, Python, Go, Ruby, PHP, C#, Java, Kotlin, Lua and Zig, generated from the API snapshot. `hook0-client` 2.0.3 on npm, PyPI and crates.io (28 August 2026), MIT - CLI: `hook0`, installed with `cargo install --git https://gitlab.com/hook0/hook0.git hook0-cli`. It sends and replays events and tunnels webhooks to localhost with `hook0 listen` - Retention: Event data for 7 days on Developer, 14 on Startup and 30 on Pro. Account data for 30 days after termination - Hosting: Clever Cloud in France, with delivery workers on Clever Cloud and Scaleway and Cloudflare for DNS and DDoS protection - Status: status.hook0.com on Better Stack, twelve components with 90 days of daily history, also served as JSON at `/index.json` - Self-hosting: Docker Compose, Kubernetes or bare metal from the same repository, SSPL-1.0. Development happens on GitLab and GitHub is a mirror - Scores: Reliability 70, Performance pending, Schema & documentation 79, Agent ergonomics 65, Security & auth 64, Payments & pricing 40, Task success pending, Maintenance & community 87, Transparency & trust 84 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service, Hook0 Cloud. · Schema & documentation, OpenAPI 3.0 document served without a login at app.hook0.com/api/v1/swagger.json, 56 operations on 38 paths (25). · Agent ergonomics, `GET /api/v1/events/` returns the 100 most recent events with no size or field parameter. · Security & auth, Service tokens are Biscuit tokens, revocable from the dashboard or the API, which the holder can narrow offline to one application, an expir… · Payments & pricing, Graded on Hook0 Cloud. · Maintenance & community, The newest tagged release is `frontend/v1.2.1` on 21 September 2026, 17 days before this check, and the default branch had commits on 8 Octo… · Transparency & trust, The server's source is public under SSPL-1.0, which the terms themselves say the OSI hasn't approved, and the SDKs and MCP server are MIT. - Sources: 33, open questions: 10, both in the full twin - Capabilities: events.webhooks-send - JSON: https://www.anchorterminal.com/api/v1/tools/hook0.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/hook0.svg` or a link to https://www.anchorterminal.com/tools/hook0 from a page on hook0.com or one of its subdomains, or the README of github.com/hook0/hook0, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use a service token narrowed to one application and an expiry. A root service token covers the whole organisation, and an application secret can delete its application 2. Send your own UUID as `event_id` on `POST /api/v1/event/`. A repeat returns `EventAlreadyIngested` (409), which means the first call succeeded 3. Create the event type before sending. Unknown types fail with `EventTypeDoesNotExist`, and `labels`, `occurred_at` and `payload_content_type` are required 4. Send `payload` as a string, with JSON serialised inside it, up to 512 KiB 5. Set `HOOK0_API_URL` for `hook0-mcp` to the origin without `/api/v1`, and set `HOOK0_READ_ONLY=true` to hide the ten write tools ## Connect ```bash cargo install hook0-mcp ``` ```bash curl -X POST "https://app.hook0.com/api/v1/event" \ -H "Authorization: Bearer $HOOK0_TOKEN" \ -H "Content-Type: application/json" \ -d '{"application_id": "", "event_type": "user.account.created", "payload": "{\"user_id\": 123}", "payload_content_type": "application/json", "labels": {"environment": "tutorial"}, "occurred_at": "2026-10-08T12:00:00Z"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/hook0 ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Hookdeck | BB | 76.9 | events.webhooks-send | https://www.anchorterminal.com/tools/hookdeck.min.md | | Ably | BB | 75 | events.webhooks-send | https://www.anchorterminal.com/tools/ably.min.md | | Svix | BB | 74 | events.webhooks-send | https://www.anchorterminal.com/tools/svix.min.md | | Upstash QStash | BB | 72.3 | events.webhooks-send | https://www.anchorterminal.com/tools/upstash-qstash.min.md | | Basecamp | B | 67.9 | events.webhooks-send | https://www.anchorterminal.com/tools/basecamp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)